CVE-2020-3191

Severity
8.6HIGH
EPSS
1.0%
top 22.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 6
Latest updateMay 24

Description

A vulnerability in DNS over IPv6 packet processing for Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to unexpectedly reload, resulting in a denial of service (DoS) condition. The vulnerability is due to improper length validation of a field in an IPv6 DNS packet. An attacker could exploit this vulnerability by sending a crafted DNS query over IPv6, which traverses the affected devic

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:HExploitability: 3.9 | Impact: 4.0

Affected Packages15 packages

NVDcisco/firepower_threat_defense6.2.36.2.3.16+2
NVDcisco/asa_5505_firmware9.4\(1\), 96.4\(0.42\)+1
NVDcisco/asa_5510_firmware9.4\(1\), 96.4\(0.42\)+1

🔴Vulnerability Details

2
GHSA
GHSA-54hx-xv6r-c55r: A vulnerability in DNS over IPv6 packet processing for Cisco Adaptive Security Appliance (ASA) Software and Firepower Threat Defense (FTD) Software co2022-05-24
CVEList
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software IPv6 DNS Denial of Service Vulnerability2020-05-06

📋Vendor Advisories

1
Cisco
Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software IPv6 DNS Denial of Service Vulnerability2020-05-06

💬Community

1
Bugzilla
CVE-2020-7106 cacti: XSS due to lack of escaping on some pages2020-01-29
CVE-2020-3191 (HIGH CVSS 8.6) | A vulnerability in DNS over IPv6 pa | cvebase.io